« Volver al listado

CVE-2026-64059

Estado: AnalizadaMedia (5.5)—

In the Linux kernel, the following vulnerability has been resolved:

netfs: Fix folio->private handling in netfs_perform_write()

Under some circumstances, netfs_perform_write() doesn't correctly manipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing to a group and pointing to a netfs_folio struct, leading to potential multiple attachments of private data with associated folio ref leaks and also leaks of netfs_folio structs or netfs_group refs.

Fix this by consolidating the place at which a folio is marked uptodate in one place and having that look at what's attached to folio->private and decide how to clean it up and then set the new group.

Leer descripción completaMostrar menos

Also, the content shouldn't be flushed if group is NULL, even if a group is specified in the netfs_group parameter, as that would be the case for a new folio. A filesystem should always specify netfs_group or never specify netfs_group.

The Sashiko auto-review tool noted that it was theoretically possible that the fpos >= ctx->zero_point section might leak if it modified a streaming write folio. This is unlikely, but with a network filesystem, third party changes can happen. It also pointed out that __netfs_set_group() would leak if called multiple times on the same folio from the "whole folio modify section".

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-64059",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
              "lessThan": "7f040243c74d72b45b22246c7d9e621fbeab44ac",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
              "lessThan": "551b5c71ee312ca7646ddb605231c1016e8cbb18",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
              "lessThan": "0969ea8370bad0e4fb6131b6a7bed9e7ec522ac7",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "8f52de0077ba3bf41e5d53d67a185700f41efce7",
              "lessThan": "ccde2ac757c713535b224233a296de40efe5212d",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "fs/netfs/buffered_write.c",
            "include/trace/events/netfs.h"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "6.12"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "6.12",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.92",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.34",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.0.11",
              "versionType": "semver",
              "lessThanOrEqual": "7.0.*"
            },
            {
              "status": "unaffected",
              "version": "7.1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "fs/netfs/buffered_write.c",
            "include/trace/events/netfs.h"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-07-19T16:17:46.407",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/0969ea8370bad0e4fb6131b6a7bed9e7ec522ac7",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/551b5c71ee312ca7646ddb605231c1016e8cbb18",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7f040243c74d72b45b22246c7d9e621fbeab44ac",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ccde2ac757c713535b224233a296de40efe5212d",
      "tags": [
        "Patch"
      ],
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix folio->private handling in netfs_perform_write()\n\nUnder some circumstances, netfs_perform_write() doesn't correctly\nmanipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing\nto a group and pointing to a netfs_folio struct, leading to potential\nmultiple attachments of private data with associated folio ref leaks and\nalso leaks of netfs_folio structs or netfs_group refs.\n\nFix this by consolidating the place at which a folio is marked uptodate in\none place and having that look at what's attached to folio->private and\ndecide how to clean it up and then set the new group.  Also, the content\nshouldn't be flushed if group is NULL, even if a group is specified in the\nnetfs_group parameter, as that would be the case for a new folio.  A\nfilesystem should always specify netfs_group or never specify netfs_group.\n\nThe Sashiko auto-review tool noted that it was theoretically possible that\nthe fpos >= ctx->zero_point section might leak if it modified a streaming\nwrite folio.  This is unlikely, but with a network filesystem, third party\nchanges can happen.  It also pointed out that __netfs_set_group() would\nleak if called multiple times on the same folio from the \"whole folio\nmodify section\"."
    }
  ],
  "lastModified": "2026-09-02T21:12:45.183",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9574AA5E-61DC-4F38-82BC-69F89AA7593C",
              "versionEndExcluding": "6.12.92",
              "versionStartIncluding": "6.12"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A4B1EF6D-18D7-4838-BC37-7499D5DCC3C0",
              "versionEndExcluding": "6.18.34",
              "versionStartIncluding": "6.13"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0520D091-FC52-4A50-AF07-70AE7D08B750",
              "versionEndExcluding": "7.0.11",
              "versionStartIncluding": "6.19"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1EF7059-E670-45F4-B422-54C40FA86390"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D38F0BF-A728-4133-A358-D44A2F7EE6D6"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC732D08-5F7B-46D9-B154-E60C7F4F0A97"
            },
            {
              "criteria": "cpe:2.3:o:linux:linux_kernel:7.1:rc4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5910A9D-F60A-409A-B486-FE66BFEBA9B9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}